Vulnerabilities > Mantis > Mantis > 0.19.4

DATE CVE VULNERABILITY TITLE RISK
2008-10-22 CVE-2008-4689 Improper Authentication vulnerability in Mantis
Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.
network
low complexity
mantis CWE-287
7.5
2008-10-22 CVE-2008-4688 Information Exposure vulnerability in Mantis
core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue's title and status via a request with a modified issue number.
network
low complexity
mantis CWE-200
5.0
2008-10-22 CVE-2008-4687 Code Injection vulnerability in Mantis
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_api.php.
network
low complexity
mantis CWE-94
critical
9.0
2008-07-27 CVE-2008-3333 Path Traversal vulnerability in Mantis
Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files via the language parameter to the user preferences page (account_prefs_update.php).
network
low complexity
mantis CWE-22
7.5
2008-07-27 CVE-2008-3332 Code Injection vulnerability in Mantis
Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary code via the value parameter.
network
low complexity
mantis CWE-94
6.5
2008-07-27 CVE-2008-3331 Cross-Site Scripting vulnerability in Mantis
Cross-site scripting (XSS) vulnerability in return_dynamic_filters.php in Mantis before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the filter_target parameter.
network
mantis CWE-79
3.5
2008-01-23 CVE-2008-0404 Cross-Site Scripting vulnerability in Mantis
Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "Most active bugs" summary.
network
mantis CWE-79
4.3
2006-02-22 CVE-2006-0841 Input Validation vulnerability in Mantis
Multiple cross-site scripting (XSS) vulnerabilities in Mantis 1.00rc4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) hide_status, (2) handler_id, (3) user_monitor, (4) reporter_id, (5) view_type, (6) show_severity, (7) show_category, (8) show_status, (9) show_resolution, (10) show_build, (11) show_profile, (12) show_priority, (13) highlight_changed, (14) relationship_type, and (15) relationship_bug parameters in (a) view_all_set.php; the (16) sort parameter in (b) manage_user_page.php; the (17) view_type parameter in (c) view_filters_page.php; and the (18) title parameter in (d) proj_doc_delete.php.
network
mantis
4.3
2006-02-22 CVE-2006-0840 Input Validation vulnerability in Mantis
manage_user_page.php in Mantis 1.00rc4 and earlier does not properly handle a sort parameter containing a ' (quote) character, which allows remote attackers to trigger a SQL error that may be repeatedly reported to a user who makes subsequent web accesses with the MANTIS_MANAGE_COOKIE cookie.
network
low complexity
mantis
5.0
2006-02-13 CVE-2006-0665 Cross-Site Scripting vulnerability in Mantis Config_Defaults_Inc.PHP
Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectors.
network
low complexity
mantis
critical
10.0